login
Login
/
Register
Search
Forums
News
Blogs
Features
Site
Home
»
Mailing list archives
»
linux-kernel
»
2008
»
February
»
10
Re: [PATCH] splice: fix user pointer access in get_iovec_page_array()
view
thread
!MAILaRCHIVE_VOTE_RePLACE
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
[view in full thread]
From:
Willy Tarreau <w@...>
To: Pekka J Enberg <penberg@...>
Cc: <torvalds@...>, <linux-kernel@...>, <stable@...>, <jens.axboe@...>, <akpm@...>, <bastian@...>, <ndenev@...>, <oliver.pntr@...>
Subject:
Re: [PATCH] splice: fix user pointer access in get_iovec_page_array()
Date: Sunday, February 10, 2008 - 7:37 pm
On Sun, Feb 10, 2008 at 04:47:57PM +0200, Pekka J Enberg wrote:
quoted text
> From: Bastian Blank <bastian@waldi.eu.org> > > The commit 8811930dc74a503415b35c4a79d14fb0b408a361 ("splice: missing user > pointer access verification") added access_ok() to copy_from_user_mmap_sem() > which only ensures we can copy the struct iovecs from userspace to the kernel > but we also must check whether we can access the actual memory region pointed > to by the struct iovec to close the local root exploit. > > Cc: <stable@kernel.org> > Cc: Jens Axboe <jens.axboe@oracle.com> > Cc: Andrew Morton <akpm@linux-foundation.org> > Signed-off-by: Pekka Enberg <penberg@cs.helsinki.fi> > --- > Bastian, can I have your Signed-off-by for this, please? Oliver, Niki, can > you please confirm this closes the hole?
Pekka, I confirm that it also closes the hole once backported to 2.6.22. Willy --
unsubscribe notice
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to
majordomo@vger.kernel.org
More majordomo info at
http://vger.kernel.org/majordomo-info.html
Please read the FAQ at
http://www.tux.org/lkml/
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
Messages in current thread:
[PATCH] splice: fix user pointer access in get_iovec_page_ar...
, Pekka J Enberg
, (Sun Feb 10, 10:47 am)
[PATCH] vmsplice exploit fix (was: splice: fix user pointer ...
, Daniel Phillips
, (Mon Feb 11, 3:29 am)
Re: [PATCH] vmsplice exploit fix (was: splice: fix user poin...
, Pekka Enberg
, (Mon Feb 11, 3:49 am)
Re: [PATCH] vmsplice exploit fix (was: splice: fix user poin...
, Daniel Phillips
, (Mon Feb 11, 4:00 am)
Re: [stable] [PATCH] vmsplice exploit fix (was: splice: fix ...
, Greg KH
, (Mon Feb 11, 3:53 am)
Re: [stable] [PATCH] vmsplice exploit fix (was: splice: fix ...
, Daniel Phillips
, (Mon Feb 11, 4:05 am)
Re: [PATCH] splice: fix user pointer access in get_iovec_pag...
, Willy Tarreau
, (Sun Feb 10, 7:37 pm)
Re: [PATCH] splice: fix user pointer access in get_iovec_pag...
, Oliver Pinter
, (Mon Feb 11, 2:24 am)
Re: [PATCH] splice: fix user pointer access in get_iovec_pag...
, Bastian Blank
, (Sun Feb 10, 11:17 am)
Re: [PATCH] splice: fix user pointer access in get_iovec_pag...
, Oliver Pinter
, (Sun Feb 10, 11:31 am)
Navigation
Create content
Mailing list archives
Recent posts
Popular discussions
linux-kernel
:
Greg Kroah-Hartman
[PATCH 001/196] Chinese: Add the known_regression URI to the HOWTO
Mark Lord
PCIe Hotplug: NFG unless I boot with card already inserted.
Davide Libenzi
[patch 7/8] fdmap v2 - implement sys_socket2
Bart Van Assche
Integration of SCST in the mainstream Linux kernel
git
:
openbsd-misc
:
freebsd-current
:
Henri Hennebert
Re: When will ZFS become stable?
Kris Kennaway
Re: loader breaks with -O2 optimizations
Petr Holub
RE: panic on boot
Ken Smith
HEADS-UP: ULE scheduler coming to 8.0-CURRENT soon...
Colocation donated by:
Who's online
There are currently
2 users
and
1168 guests
online.
Online users
shoesbymarc
Nelson
Syndicate